Field-Level Access Control Flaw in Payload CMS
CVE-2026-105855
7.6HIGH
What is CVE-2026-105855?
A significant security issue exists in Payload, an open-source headless content management system, where the server does not adequately enforce restrictions on field-level access to the password field within the authentication collection. This flaw affects all versions of Payload prior to 3.90.0 and canary versions prior to 4.0.0-canary.34. The vulnerability enables unauthorized users to potentially modify authentication credentials, leading to serious implications for data security. This issue has been addressed in the latest updates, ensuring improved access control mechanisms are in place.
Affected Version(s)
payload < 3.90.0 < 3.90.0
payload >= 4.0.0-canary.0, < 4.0.0-canary.34 < 4.0.0-canary.0, 4.0.0-canary.34
